Skip to content
1,120 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server in Rust; a public index at the API root1//! The OpenAPI document, generated from the same list the routes are.
Merge branch 'worktree-agent-ab2e39e11a6493412'2//!
3//! The docs site builds its API reference from a copy of this document,
4//! `apps/docs/src/data/openapi.json`. A test keeps the copy current: run
5//! `G1T_WRITE_OPENAPI=1 cargo test -p g1t-api openapi` to rewrite it.
API and MCP server in Rust; a public index at the API root6
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step7use g1t_contracts::scopes::scope_for;
API and MCP server in Rust; a public index at the API root8use serde_json::{Map, Value, json};
9
10use crate::operations::Op;
Rulesets over REST and MCP11use crate::rules::RulesOp;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar12use crate::security::SecurityOp;
API and MCP server in Rust; a public index at the API root13use crate::rest::{ROUTES, Route};
14
Merge branch 'worktree-agent-ab2e39e11a6493412'15/// The sections of the API reference: a name, what it covers, and its
16/// operations in the order a reader meets them.
17const SECTIONS: &[(&str, &str, &[Op])] = &[
18 (
19 "Accounts",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look20 "Signing in from a tool, who a token acts as, and your email addresses.",
21 &[Op::Whoami, Op::ListEmails, Op::AddEmail, Op::RemoveEmail, Op::UpdateEmailSettings],
Merge branch 'worktree-agent-ab2e39e11a6493412'22 ),
23 (
API: notifications over REST and MCP, with notifications scopes24 "Notifications",
25 "Your inbox: a thread for each thing you were told about (an issue, a pull request, a workflow on a branch, a deployment), why you were told, and what you subscribe to and watch. Your own: personal tokens and sessions only.",
26 &[
27 Op::ListNotifications,
28 Op::MarkNotificationsRead,
29 Op::GetNotificationThread,
30 Op::MarkThreadRead,
31 Op::MarkThreadDone,
32 Op::SaveThread,
33 Op::SnoozeThread,
34 Op::GetThreadSubscription,
35 Op::SetThreadSubscription,
36 Op::DeleteThreadSubscription,
37 Op::GetRepoSubscription,
38 Op::SetRepoSubscription,
39 Op::DeleteRepoSubscription,
40 Op::ListWatchedRepos,
41 ],
42 ),
43 (
API: pinned projects over REST and MCP44 "Pinned projects",
45 "The projects you keep at the top of a workspace's sidebar, in your order, up to eight a workspace. Your own: personal tokens and sessions only.",
46 &[Op::ListPinnedProjects, Op::PinProject, Op::UnpinProject, Op::ReorderPinnedProjects],
47 ),
48 (
Merge branch 'worktree-agent-ab2e39e11a6493412'49 "Workspaces",
50 "A workspace owns repositories and is the first part of their address. People and agents work in workspaces.",
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily51 &[Op::CreateWorkspace, Op::UpdateWorkspace, Op::DeleteWorkspace],
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look52 ),
53 (
54 "Invites",
55 "While g1t is invite-only, every new account needs an invite. Your invites, and inviting people into a workspace by email.",
56 &[
57 Op::ListInvites,
58 Op::CreateInvite,
59 Op::RevokeInvite,
60 Op::ListWorkspaceInvites,
61 Op::InviteMember,
62 Op::RevokeWorkspaceInvite,
63 ],
Merge branch 'worktree-agent-ab2e39e11a6493412'64 ),
65 (
Usage, Billing settings and prepaid AI credit; fixes from the UX audit66 "Billing",
67 "A workspace's usage, its budget, its AI credit and its invoices. Members read them; owners change the budget and buy credit, as people. g1t's agents never change billing.",
68 &[
69 Op::GetUsage,
70 Op::GetBudget,
71 Op::SetBudget,
72 Op::GetAiCredit,
73 Op::BuyAiCredit,
74 Op::ListInvoices,
75 Op::GetBillingDetails,
76 ],
77 ),
78 (
Merge branch 'worktree-agent-ab2e39e11a6493412'79 "Repositories",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look80 "A repository, how it handles pull requests, and its timeline: renaming, archiving, moving and deleting it.",
Merge branch 'worktree-agent-ab2e39e11a6493412'81 &[
82 Op::ListRepos,
83 Op::CreateRepo,
84 Op::GetRepo,
85 Op::UpdateRepo,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look86 Op::RenameRepo,
87 Op::RenameBranch,
88 Op::SetRepoVisibility,
89 Op::ArchiveRepo,
90 Op::UnarchiveRepo,
91 Op::TransferRepo,
92 Op::DeleteRepo,
93 Op::ListDeletedRepos,
94 Op::RestoreRepo,
95 Op::PurgeRepo,
Merge branch 'worktree-agent-ab2e39e11a6493412'96 Op::GetRepoSettings,
97 Op::UpdateRepoSettings,
Fast pages, required checks on the branch, self-hosted runners, honest incidents98 Op::ListCheckNames,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar99 Op::GetCodeownersErrors,
Merge branch 'worktree-agent-ab2e39e11a6493412'100 Op::ListEvents,
101 ],
102 ),
103 (
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look104 "Access",
105 "Who can do what in a repository: repository roles, people given a role on one repository (outside collaborators when they are not members), invitations, and a workspace's base permission.",
106 &[
107 Op::ListCollaborators,
108 Op::AddCollaborator,
109 Op::UpdateCollaborator,
110 Op::RemoveCollaborator,
111 Op::GetCollaboratorPermission,
112 Op::ListRepoInvitations,
113 Op::RevokeRepoInvitation,
114 Op::ListMyRepoInvitations,
115 Op::AcceptRepoInvitation,
116 Op::DeclineRepoInvitation,
117 Op::SetBasePermission,
118 Op::ListOutsideCollaborators,
119 ],
120 ),
121 (
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar122 "Teams",
123 "Groups of a workspace's members: given a role on repositories together, mentioned together as @workspace/team, and asked to review together. Any member may create a team; the workspace's owners and the team's maintainers manage it.",
124 &[
125 Op::ListTeams,
126 Op::CreateTeam,
127 Op::GetTeam,
128 Op::UpdateTeam,
129 Op::DeleteTeam,
130 Op::ListTeamMembers,
131 Op::SetTeamMember,
132 Op::RemoveTeamMember,
133 Op::ListChildTeams,
134 Op::ListTeamRepos,
135 Op::SetTeamRepo,
136 Op::RemoveTeamRepo,
137 Op::SetTeamReviewAssignment,
138 Op::ListUserTeams,
139 ],
140 ),
141 (
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily142 "Security",
143 "Secrets found in what is pushed and in a repository's history, and dependencies with known vulnerabilities: listing the alerts, and dismissing or reopening them.",
144 &[Op::ListSecurityAlerts, Op::DismissSecurityAlert, Op::ReopenSecurityAlert],
145 ),
146 (
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar147 "Secret scanning",
148 "Secrets found in pushes and history, where each one is, pushing past push protection with a reason (and asking for approval when the workspace delegates bypasses), checking with a secret's issuer whether it still works, and custom patterns.",
149 &[
150 Op::Security(SecurityOp::ListSecretAlerts),
151 Op::Security(SecurityOp::GetSecretAlert),
152 Op::Security(SecurityOp::UpdateSecretAlert),
153 Op::Security(SecurityOp::ListSecretLocations),
154 Op::Security(SecurityOp::BypassPushProtection),
155 Op::Security(SecurityOp::CheckSecretValidity),
156 Op::Security(SecurityOp::ListBypassRequests),
157 Op::Security(SecurityOp::ReviewBypassRequest),
158 Op::Security(SecurityOp::ListCustomPatterns),
159 Op::Security(SecurityOp::CreateCustomPattern),
160 Op::Security(SecurityOp::UpdateCustomPattern),
161 Op::Security(SecurityOp::DeleteCustomPattern),
162 Op::Security(SecurityOp::DryRunCustomPattern),
163 ],
164 ),
165 (
166 "Code scanning",
167 "Results of static analysis tools, uploaded as SARIF: alerts on the default branch, the analyses that made them, uploads, and putting g1t on an alert to fix it.",
168 &[
169 Op::Security(SecurityOp::ListCodeAlerts),
170 Op::Security(SecurityOp::GetCodeAlert),
171 Op::Security(SecurityOp::UpdateCodeAlert),
172 Op::Security(SecurityOp::ListAnalyses),
173 Op::Security(SecurityOp::UploadSarif),
174 Op::Security(SecurityOp::GetSarifUpload),
175 Op::Security(SecurityOp::FixAlert),
176 ],
177 ),
178 (
179 "Supply chain",
180 "What a repository depends on: vulnerability alerts, the dependency graph, an SPDX SBOM of it, and comparing two commits' dependencies as dependency review does.",
181 &[
182 Op::Security(SecurityOp::ListVulnerabilityAlerts),
183 Op::Security(SecurityOp::GetVulnerabilityAlert),
184 Op::Security(SecurityOp::UpdateVulnerabilityAlert),
185 Op::Security(SecurityOp::GetDependencyGraph),
186 Op::Security(SecurityOp::GetSbom),
187 Op::Security(SecurityOp::CompareDependencies),
188 ],
189 ),
190 (
191 "Security settings",
192 "When pull request checks fail, dependency review's policy, delegated bypass and validity checks, and a workspace's security overview.",
193 &[
194 Op::Security(SecurityOp::GetSettings),
195 Op::Security(SecurityOp::UpdateSettings),
196 Op::Security(SecurityOp::GetWorkspaceSettings),
197 Op::Security(SecurityOp::UpdateWorkspaceSettings),
198 Op::Security(SecurityOp::GetOverview),
199 ],
200 ),
201 (
Rulesets over REST and MCP202 "Rules",
203 "Rulesets: what may happen to a repository's branches and tags and what a pull request needs before it merges, for a repository or across a workspace; the rules that hold for one branch; and how they judged each push and merge, with insights.",
204 &[
205 Op::Rules(RulesOp::ListRepoRulesets),
206 Op::Rules(RulesOp::CreateRepoRuleset),
207 Op::Rules(RulesOp::GetRepoRuleset),
208 Op::Rules(RulesOp::UpdateRepoRuleset),
209 Op::Rules(RulesOp::DeleteRepoRuleset),
210 Op::Rules(RulesOp::GetBranchRules),
211 Op::Rules(RulesOp::ListRuleEvaluations),
212 Op::Rules(RulesOp::ListWorkspaceRulesets),
213 Op::Rules(RulesOp::CreateWorkspaceRuleset),
214 Op::Rules(RulesOp::GetWorkspaceRuleset),
215 Op::Rules(RulesOp::UpdateWorkspaceRuleset),
216 Op::Rules(RulesOp::DeleteWorkspaceRuleset),
217 Op::Rules(RulesOp::ListWorkspaceRuleEvaluations),
218 ],
219 ),
220 (
Merge branch 'worktree-agent-ab2e39e11a6493412'221 "Issues",
222 "What should change in a repository, with labels and comments. Issues and pull requests share one sequence of numbers.",
223 &[
224 Op::ListIssues,
225 Op::CreateIssue,
226 Op::GetIssue,
227 Op::UpdateIssue,
228 Op::CloseIssue,
229 Op::ReopenIssue,
230 Op::AssignIssue,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step231 Op::Delegate,
Merge branch 'worktree-agent-ab2e39e11a6493412'232 Op::AddComment,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar233 Op::ListIssueLabels,
234 Op::AddIssueLabels,
235 Op::SetIssueLabels,
236 Op::RemoveIssueLabels,
237 ],
238 ),
239 (
240 "Labels and milestones",
241 "A repository's labels, which issues and pull requests carry by name, and its milestones, which gather them under a goal and a due date.",
242 &[
Merge branch 'worktree-agent-ab2e39e11a6493412'243 Op::ListLabels,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar244 Op::CreateLabel,
245 Op::UpdateLabel,
246 Op::DeleteLabel,
247 Op::AddDefaultLabels,
248 Op::ListMilestones,
249 Op::CreateMilestone,
250 Op::GetMilestone,
251 Op::UpdateMilestone,
252 Op::DeleteMilestone,
Merge branch 'worktree-agent-ab2e39e11a6493412'253 ],
254 ),
255 (
256 "Plans",
257 "An outcome turned into the issues that would get there, with the order they must merge in.",
258 &[Op::PlanWork, Op::GetPlan, Op::ApplyPlan],
259 ),
260 (
261 "Pull requests",
262 "A proposed change in its own fork or on a branch. Several can be made for one issue; the one merged resolves it.",
263 &[
264 Op::ListPullRequests,
265 Op::CreatePullRequest,
266 Op::GetPullRequest,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar267 Op::UpdatePullRequest,
Merge branch 'worktree-agent-ab2e39e11a6493412'268 Op::GetPullRequestChanges,
269 Op::MarkPullRequestReady,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar270 Op::RequestReviewers,
271 Op::RemoveRequestedReviewers,
Merge branch 'worktree-agent-ab2e39e11a6493412'272 Op::ReviewPullRequest,
273 Op::MergePullRequest,
274 Op::ClosePullRequest,
275 Op::GetMergeQueue,
276 Op::MessageAgent,
277 Op::AnswerMessage,
278 Op::TakeMessages,
279 ],
280 ),
281 (
282 "Sessions",
283 "The record of how a pull request was made: prompts, reasoning and the tools that ran.",
284 &[Op::ReadSession, Op::RecordSession],
285 ),
286 (
Agents and memory, checks and conflicts, profiles, slug renames, custom domains287 "Memory",
288 "What agents and people learned that the next agent should know, for one project or across a workspace. Members and g1t's agents only; never a secret.",
289 &[Op::Remember, Op::Recall],
290 ),
291 (
Search across all of g1t, Explore, and a command palette292 "Search",
293 "One search across all of g1t: repositories, code, issues, pull requests, people and workspaces. Public content for everyone, and private content in workspaces you belong to.",
294 &[Op::Search],
295 ),
296 (
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API297 "Context",
298 "A workspace's context hub: a catalog of what it builds and runs, built from its repositories, deployments and integrations, and one search across the catalog, docs, issues, pull requests and memory.",
299 &[Op::SearchContext, Op::GetEntity],
300 ),
301 (
Merge branch 'worktree-agent-ab2e39e11a6493412'302 "Actions",
303 "GitHub Actions workflows in .g1t/workflows, their runs, and their jobs' logs.",
304 &[
305 Op::ListWorkflows,
306 Op::ListWorkflowRuns,
307 Op::GetWorkflowRun,
308 Op::GetJobLogs,
309 Op::DispatchWorkflow,
310 Op::CancelWorkflowRun,
311 Op::RerunWorkflowRun,
312 Op::UpdateWorkflow,
313 ],
314 ),
315 (
316 "Secrets and variables",
317 "Values that workflows and deployments read, per repository or for a whole workspace, with a row per environment.",
318 &[
319 Op::ListActionsSecrets,
320 Op::SetActionsSecret,
321 Op::DeleteActionsSecret,
322 Op::ListActionsVariables,
323 Op::SetActionsVariable,
324 Op::DeleteActionsVariable,
325 ],
326 ),
327 (
Fast pages, required checks on the branch, self-hosted runners, honest incidents328 "Runners",
329 "Self-hosted runners: your own machines, which run your workflow jobs (and, if you choose, your agents' work) for $0 of g1t compute. They register with a short-lived token and only ever connect out.",
330 &[
331 Op::ListRunners,
332 Op::CreateRunnerRegistrationToken,
333 Op::RemoveRunner,
334 Op::ListRunnerGroups,
335 Op::CreateRunnerGroup,
336 Op::UpdateRunnerGroup,
337 Op::DeleteRunnerGroup,
338 Op::GetRunnerSettings,
339 Op::UpdateRunnerSettings,
340 ],
341 ),
342 (
Merge branch 'worktree-agent-ab2e39e11a6493412'343 "Webhooks",
344 "Signed HTTPS requests sent to your own address as things happen, for a repository or a whole workspace.",
345 &[
346 Op::ListWebhooks,
347 Op::CreateWebhook,
348 Op::UpdateWebhook,
349 Op::DeleteWebhook,
350 Op::PingWebhook,
351 Op::ListWebhookDeliveries,
352 Op::RedeliverWebhook,
353 ],
354 ),
355 (
356 "Integrations",
357 "A workspace's connections to outside systems: model providers, alert sources and issue trackers.",
358 &[
359 Op::ListIntegrations,
360 Op::ConnectIntegration,
361 Op::DisconnectIntegration,
362 Op::TestIntegration,
363 Op::GetModelRoutes,
364 Op::SetModelRoutes,
365 Op::GetContext,
366 Op::ImportIssue,
367 ],
368 ),
369];
370
API and MCP server in Rust; a public index at the API root371/// The section of the API reference an operation is listed under.
372fn tag(op: Op) -> &'static str {
Merge branch 'worktree-agent-ab2e39e11a6493412'373 SECTIONS
API and MCP server in Rust; a public index at the API root374 .iter()
Merge branch 'worktree-agent-ab2e39e11a6493412'375 .find(|(_, _, ops)| ops.contains(&op))
376 .map_or("Repositories", |(name, _, _)| name)
377}
378
379/// What an operation's page is called, as a short sentence.
380fn title(op: Op) -> &'static str {
381 match op {
382 Op::Whoami => "Get the current user",
383 Op::CreateWorkspace => "Create a workspace",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look384 Op::DeleteWorkspace => "Delete a workspace",
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily385 Op::UpdateWorkspace => "Update a workspace",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look386 Op::ListEmails => "List your email addresses",
387 Op::AddEmail => "Add an email address",
388 Op::RemoveEmail => "Remove an email address",
389 Op::UpdateEmailSettings => "Change your email settings",
390 Op::ListInvites => "List your invites",
391 Op::CreateInvite => "Create an invite",
392 Op::RevokeInvite => "Revoke an invite",
393 Op::ListWorkspaceInvites => "List a workspace's invites",
394 Op::InviteMember => "Invite someone to a workspace",
395 Op::RevokeWorkspaceInvite => "Revoke a workspace's invite",
396 Op::TransferRepo => "Transfer a repository",
397 Op::RenameRepo => "Rename a repository",
398 Op::RenameBranch => "Rename a branch",
399 Op::ArchiveRepo => "Archive a repository",
400 Op::UnarchiveRepo => "Unarchive a repository",
401 Op::SetRepoVisibility => "Change a repository's visibility",
402 Op::DeleteRepo => "Delete a repository",
403 Op::ListDeletedRepos => "List recently deleted repositories",
404 Op::RestoreRepo => "Restore a deleted repository",
405 Op::PurgeRepo => "Purge a deleted repository",
Merge branch 'worktree-agent-ab2e39e11a6493412'406 Op::ListRepos => "List repositories",
407 Op::GetRepo => "Get a repository",
408 Op::CreateRepo => "Create a repository",
409 Op::UpdateRepo => "Update a repository",
410 Op::GetRepoSettings => "Get repository settings",
411 Op::UpdateRepoSettings => "Update repository settings",
Fast pages, required checks on the branch, self-hosted runners, honest incidents412 Op::ListCheckNames => "List check names",
Merge branch 'worktree-agent-ab2e39e11a6493412'413 Op::GetMergeQueue => "Get the merge queue",
414 Op::MessageAgent => "Message an agent",
415 Op::AnswerMessage => "Answer a message",
416 Op::TakeMessages => "Take new messages",
Agents and memory, checks and conflicts, profiles, slug renames, custom domains417 Op::Remember => "Remember something",
418 Op::Recall => "Recall memory",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API419 Op::SearchContext => "Search the context hub",
420 Op::GetEntity => "Get a catalog entry",
Search across all of g1t, Explore, and a command palette421 Op::Search => "Search g1t",
Merge branch 'worktree-agent-ab2e39e11a6493412'422 Op::ListIssues => "List issues",
423 Op::GetIssue => "Get an issue",
424 Op::CreateIssue => "Create an issue",
425 Op::UpdateIssue => "Update an issue",
426 Op::CloseIssue => "Close an issue",
427 Op::ReopenIssue => "Reopen an issue",
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent428 Op::AssignIssue => "Assign an issue to g1t",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step429 Op::Delegate => "Put an agent on it",
Merge branch 'worktree-agent-ab2e39e11a6493412'430 Op::PlanWork => "Plan work",
431 Op::GetPlan => "Get a plan",
432 Op::ApplyPlan => "Apply a plan",
433 Op::ListLabels => "List labels",
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar434 Op::CreateLabel => "Create a label",
435 Op::UpdateLabel => "Update a label",
436 Op::DeleteLabel => "Delete a label",
437 Op::AddDefaultLabels => "Add the default labels",
438 Op::ListIssueLabels => "List an issue's labels",
439 Op::AddIssueLabels => "Add labels to an issue",
440 Op::SetIssueLabels => "Set an issue's labels",
441 Op::RemoveIssueLabels => "Remove labels from an issue",
442 Op::ListMilestones => "List milestones",
443 Op::GetMilestone => "Get a milestone",
444 Op::CreateMilestone => "Create a milestone",
445 Op::UpdateMilestone => "Update a milestone",
446 Op::DeleteMilestone => "Delete a milestone",
447 Op::UpdatePullRequest => "Update a pull request",
Merge branch 'worktree-agent-ab2e39e11a6493412'448 Op::AddComment => "Add a comment",
449 Op::ReviewPullRequest => "Review a pull request",
450 Op::ListPullRequests => "List pull requests",
451 Op::GetPullRequest => "Get a pull request",
452 Op::CreatePullRequest => "Create a pull request",
453 Op::RecordSession => "Record session entries",
454 Op::ReadSession => "Read a session",
455 Op::MarkPullRequestReady => "Mark a pull request ready",
456 Op::ClosePullRequest => "Close a pull request",
457 Op::GetPullRequestChanges => "Get a pull request's changes",
458 Op::MergePullRequest => "Merge a pull request",
459 Op::ListEvents => "List repository events",
460 Op::ListIntegrations => "List integrations",
461 Op::ConnectIntegration => "Connect an integration",
462 Op::DisconnectIntegration => "Disconnect an integration",
463 Op::TestIntegration => "Test an integration",
464 Op::GetContext => "Look up a ticket",
465 Op::ImportIssue => "Import an issue",
466 Op::GetModelRoutes => "Get model routes",
467 Op::SetModelRoutes => "Set model routes",
468 Op::ListWebhooks => "List webhooks",
469 Op::CreateWebhook => "Create a webhook",
470 Op::UpdateWebhook => "Update a webhook",
471 Op::DeleteWebhook => "Delete a webhook",
472 Op::PingWebhook => "Ping a webhook",
473 Op::ListWebhookDeliveries => "List webhook deliveries",
474 Op::RedeliverWebhook => "Redeliver a webhook delivery",
475 Op::ListWorkflows => "List workflows",
476 Op::ListWorkflowRuns => "List workflow runs",
477 Op::GetWorkflowRun => "Get a workflow run",
478 Op::GetJobLogs => "Get a job's log",
479 Op::DispatchWorkflow => "Run a workflow",
480 Op::CancelWorkflowRun => "Cancel a workflow run",
481 Op::RerunWorkflowRun => "Re-run a workflow run",
482 Op::UpdateWorkflow => "Turn a workflow on or off",
483 Op::ListActionsSecrets => "List secrets",
484 Op::SetActionsSecret => "Set a secret",
485 Op::DeleteActionsSecret => "Delete a secret",
486 Op::ListActionsVariables => "List variables",
487 Op::SetActionsVariable => "Set a variable",
488 Op::DeleteActionsVariable => "Delete a variable",
Fast pages, required checks on the branch, self-hosted runners, honest incidents489 Op::ListRunners => "List self-hosted runners",
490 Op::ListRunnerGroups => "List runner groups",
491 Op::GetRunnerSettings => "Get runner settings",
492 Op::CreateRunnerRegistrationToken => "Create a runner registration token",
493 Op::RemoveRunner => "Remove a self-hosted runner",
494 Op::CreateRunnerGroup => "Create a runner group",
495 Op::UpdateRunnerGroup => "Change a runner group",
496 Op::DeleteRunnerGroup => "Delete a runner group",
497 Op::UpdateRunnerSettings => "Change runner settings",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look498 Op::ListCollaborators => "List who has access",
499 Op::AddCollaborator => "Add a collaborator",
500 Op::UpdateCollaborator => "Change a collaborator's role",
501 Op::RemoveCollaborator => "Remove a collaborator",
502 Op::GetCollaboratorPermission => "Get someone's permission",
503 Op::ListRepoInvitations => "List a repository's invitations",
504 Op::RevokeRepoInvitation => "Revoke a repository invitation",
505 Op::ListMyRepoInvitations => "List your repository invitations",
506 Op::AcceptRepoInvitation => "Accept a repository invitation",
507 Op::DeclineRepoInvitation => "Decline a repository invitation",
508 Op::SetBasePermission => "Set the base permission",
509 Op::ListOutsideCollaborators => "List outside collaborators",
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily510 Op::ListSecurityAlerts => "List security alerts",
511 Op::DismissSecurityAlert => "Dismiss a security alert",
512 Op::ReopenSecurityAlert => "Reopen a security alert",
API: notifications over REST and MCP, with notifications scopes513 Op::ListNotifications => "List notifications",
514 Op::MarkNotificationsRead => "Mark notifications read",
515 Op::GetNotificationThread => "Get a thread",
516 Op::MarkThreadRead => "Mark a thread read",
517 Op::MarkThreadDone => "Mark a thread done",
518 Op::SaveThread => "Save a thread",
519 Op::SnoozeThread => "Snooze a thread",
520 Op::GetThreadSubscription => "Get a thread subscription",
521 Op::SetThreadSubscription => "Set a thread subscription",
522 Op::DeleteThreadSubscription => "Unsubscribe from a thread",
523 Op::GetRepoSubscription => "Get how you watch a repository",
524 Op::SetRepoSubscription => "Watch a repository",
525 Op::DeleteRepoSubscription => "Stop watching a repository",
526 Op::ListWatchedRepos => "List repositories you watch",
API: pinned projects over REST and MCP527 Op::ListPinnedProjects => "List your pinned projects",
Usage, Billing settings and prepaid AI credit; fixes from the UX audit528 Op::GetUsage => "Get a workspace's usage",
529 Op::GetBudget => "Get a workspace's budget",
530 Op::SetBudget => "Change a workspace's budget",
531 Op::GetAiCredit => "Get a workspace's AI credit",
532 Op::BuyAiCredit => "Buy AI credit",
533 Op::ListInvoices => "List a workspace's invoices",
534 Op::GetBillingDetails => "Get a workspace's billing details",
API: pinned projects over REST and MCP535 Op::PinProject => "Pin a project",
536 Op::UnpinProject => "Unpin a project",
537 Op::ReorderPinnedProjects => "Reorder your pinned projects",
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar538 Op::ListTeams => "List teams",
539 Op::GetTeam => "Get a team",
540 Op::CreateTeam => "Create a team",
541 Op::UpdateTeam => "Update a team",
542 Op::DeleteTeam => "Delete a team",
543 Op::ListTeamMembers => "List a team's members",
544 Op::SetTeamMember => "Add or change a team member",
545 Op::RemoveTeamMember => "Remove a team member",
546 Op::ListChildTeams => "List child teams",
547 Op::ListTeamRepos => "List a team's repositories",
548 Op::SetTeamRepo => "Give a team a role on a repository",
549 Op::RemoveTeamRepo => "Remove a team from a repository",
550 Op::SetTeamReviewAssignment => "Set a team's review assignment",
551 Op::ListUserTeams => "List someone's teams",
552 Op::RequestReviewers => "Request reviewers",
553 Op::RemoveRequestedReviewers => "Remove requested reviewers",
554 Op::GetCodeownersErrors => "List CODEOWNERS errors",
555 Op::Security(op) => op.title(),
Rulesets over REST and MCP556 Op::Rules(op) => op.title(),
API and MCP server in Rust; a public index at the API root557 }
558}
559
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look560/// Why an operation can be refused with `402 payment_required`, if it
561/// can: the ones that start an agent, when the workspace has no credit,
562/// and the ones that make a repository private in a workspace, when a free
563/// workspace's private storage has no room for it.
564fn may_need_payment(op: Op) -> Option<&'static str> {
565 match op {
566 Op::AssignIssue | Op::PlanWork | Op::ApplyPlan => Some("The workspace has no agent credit."),
567 Op::UpdateRepo | Op::SetRepoVisibility | Op::TransferRepo => Some(
568 "A free workspace's private storage has no room for this private repository.",
569 ),
570 _ => None,
571 }
Merge branch 'worktree-agent-ab2e39e11a6493412'572}
573
574/// What the reference says beyond each operation's own description, keyed
575/// by operation id, written by hand from what the services return: `notes`
576/// (Markdown, added to the description) and example `params` (path),
577/// `query`, `request` (body) and `response`.
578const REFERENCE: &str = include_str!("reference.json");
579
580fn examples() -> Map<String, Value> {
581 match serde_json::from_str(REFERENCE) {
582 Ok(Value::Object(examples)) => examples,
583 _ => Map::new(),
API and MCP server in Rust; a public index at the API root584 }
585}
586
Agents as a team: lifecycle, merge queue, billing and a new shell587/// `/repos/:owner/:name` as OpenAPI writes it: `/repos/{owner}/{name}`.
API and MCP server in Rust; a public index at the API root588fn openapi_path(route: &Route) -> String {
589 route
590 .path
591 .split('/')
592 .map(|segment| match segment.strip_prefix(':') {
593 Some(name) => format!("{{{name}}}"),
594 None => segment.to_owned(),
595 })
596 .collect::<Vec<_>>()
597 .join("/")
598}
599
600fn error_response(description: &str) -> Value {
601 json!({
602 "description": description,
603 "content": { "application/json": { "schema": { "$ref": "#/components/schemas/Error" } } },
604 })
605}
606
Merge branch 'worktree-agent-ab2e39e11a6493412'607/// A parameter in the path or the query, described by the operation's
608/// input schema where it has the same name.
609fn parameter(name: &str, place: &str, required: bool, schema: Option<&Value>) -> Value {
610 let mut schema = schema.cloned().unwrap_or_else(|| json!({ "type": "string" }));
611 let description = match name {
612 "owner" => Some(Value::from("The workspace that owns the repository.")),
613 "name" => Some(Value::from("The repository's name.")),
614 _ => schema.as_object_mut().and_then(|schema| schema.remove("description")),
615 };
616 let mut parameter = json!({
617 "name": name,
618 "in": place,
619 "required": required,
620 "schema": schema,
621 });
622 if let Some(description) = description {
623 parameter["description"] = description;
624 }
625 parameter
626}
627
628/// The operation id of a route. An operation reached at a workspace's
629/// address as well as a repository's is documented once for each, with its
630/// own id; GitHub's alternative addresses for one operation keep GitHub's
631/// names.
632fn operation_id(route: &Route) -> String {
633 let op = route.op;
634 let base = match (route.method, route.path.rsplit('/').next().unwrap_or_default()) {
635 ("PUT", "enable") => "enable_workflow".to_owned(),
636 ("PUT", "disable") => "disable_workflow".to_owned(),
637 ("POST", "rerun-failed-jobs") => "rerun_failed_jobs".to_owned(),
638 ("PATCH", ":setting") => "update_actions_variable".to_owned(),
639 ("GET", "runs") if route.path.contains("/workflows/:workflow/") => "list_runs_of_workflow".to_owned(),
API: notifications over REST and MCP, with notifications scopes640 // One repository's notifications, and an issue's subscription by
641 // its number rather than a thread's id.
642 (_, "notifications") if route.path.starts_with("/repos/") => match op {
643 Op::ListNotifications => "list_repo_notifications".to_owned(),
644 _ => "mark_repo_notifications_read".to_owned(),
645 },
646 (method, "subscription") if route.path.contains("/issues/:number/") => match method {
647 "GET" => "get_issue_subscription".to_owned(),
648 "PUT" => "set_issue_subscription".to_owned(),
649 _ => "delete_issue_subscription".to_owned(),
650 },
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar651 // One label off an issue, by its name in the path.
652 ("DELETE", ":label") if route.path.contains("/issues/:number/") => "remove_issue_label".to_owned(),
API: notifications over REST and MCP, with notifications scopes653 ("DELETE", "saved") => "unsave_thread".to_owned(),
654 ("DELETE", "snooze") => "unsnooze_thread".to_owned(),
Merge branch 'worktree-agent-ab2e39e11a6493412'655 _ => op.name().to_owned(),
656 };
657 if route.path.starts_with("/workspaces/") && ROUTES.iter().any(|other| other.op == op && other.path.starts_with("/repos/")) {
658 format!("{base}_for_workspace")
659 } else {
660 base
661 }
662}
663
664/// The summary of a route: its operation's title, or for one of GitHub's
665/// alternative addresses, what that address does.
666fn summary(route: &Route, id: &str) -> String {
667 let base = match id.trim_end_matches("_for_workspace") {
668 "enable_workflow" => "Turn a workflow on",
669 "disable_workflow" => "Turn a workflow off",
670 "rerun_failed_jobs" => "Re-run failed jobs",
671 "update_actions_variable" => "Update a variable",
672 "list_runs_of_workflow" => "List a workflow's runs",
API: notifications over REST and MCP, with notifications scopes673 "list_repo_notifications" => "List a repository's notifications",
674 "mark_repo_notifications_read" => "Mark a repository's notifications read",
675 "get_issue_subscription" => "Get your subscription to an issue",
676 "set_issue_subscription" => "Subscribe to an issue",
677 "delete_issue_subscription" => "Unsubscribe from an issue",
678 "unsave_thread" => "Unsave a thread",
679 "unsnooze_thread" => "Bring a snoozed thread back",
Merge branch 'worktree-agent-ab2e39e11a6493412'680 _ => title(route.op),
681 };
682 if id.ends_with("_for_workspace") {
683 format!("{base} for a workspace")
684 } else {
685 base.to_owned()
686 }
687}
688
API and MCP server in Rust; a public index at the API root689fn operation(route: &Route) -> Value {
690 let op = route.op;
691 let path_params: Vec<&str> = route.params().collect();
692 // `owner` and `name` in the path stand for the operation's `repo` input.
693 let covered = |name: &str| name == "repo" || path_params.contains(&name);
Merge branch 'worktree-agent-ab2e39e11a6493412'694 let all_properties = op.properties();
695 let mut properties = all_properties.clone();
API and MCP server in Rust; a public index at the API root696 properties.retain(|name, _| !covered(name));
697 let required: Vec<String> = op
698 .required()
699 .into_iter()
700 .filter(|name| !covered(name))
701 .collect();
702
703 let mut parameters: Vec<Value> = path_params
704 .iter()
Merge branch 'worktree-agent-ab2e39e11a6493412'705 .map(|name| parameter(name, "path", true, all_properties.get(*name)))
API and MCP server in Rust; a public index at the API root706 .collect();
707 let mut body = Value::Null;
708 if route.method == "GET" {
709 for (name, key) in route.query {
Merge branch 'worktree-agent-ab2e39e11a6493412'710 parameters.push(parameter(
711 name,
712 "query",
713 required.iter().any(|required| required == key),
714 properties.get(*key),
715 ));
API and MCP server in Rust; a public index at the API root716 }
717 } else if !properties.is_empty() {
718 let mut schema = json!({ "type": "object", "properties": properties });
719 if !required.is_empty() {
720 schema["required"] = json!(required);
721 }
722 body = json!({
723 "required": !required.is_empty(),
724 "content": { "application/json": { "schema": schema } },
725 });
726 }
727
Merge branch 'worktree-agent-ab2e39e11a6493412'728 let id = operation_id(route);
729 let mut responses = Map::new();
730 responses.insert(
731 "200".into(),
732 json!({
733 "description": "Success.",
734 "content": { "application/json": { "schema": {} } },
735 }),
736 );
737 responses.insert(
738 "401".into(),
739 error_response("A token is required, or the one sent is not valid."),
740 );
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look741 if let Some(reason) = may_need_payment(op) {
742 responses.insert("402".into(), error_response(reason));
Merge branch 'worktree-agent-ab2e39e11a6493412'743 }
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step744 responses.insert(
745 "403".into(),
746 error_response("Signed in, but not allowed to do this: the role you have is not enough, or the token lacks the scope it needs, which `needed_scope` names."),
747 );
Search across all of g1t, Explore, and a command palette748 if !matches!(op, Op::Whoami | Op::ListRepos | Op::Search) {
Merge branch 'worktree-agent-ab2e39e11a6493412'749 responses.insert("404".into(), error_response("It does not exist, or you cannot see it."));
750 }
751 if route.method != "GET" {
752 responses.insert(
753 "409".into(),
754 error_response("The request conflicts with the current state."),
755 );
756 }
757 if op != Op::Whoami {
758 responses.insert("422".into(), error_response("The input is not valid."));
759 }
760 // Public data can be read without a token; everything else needs one.
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step761 let scope: Vec<&str> = scope_for(op.name()).map(|scope| scope.as_str()).into_iter().collect();
Merge branch 'worktree-agent-ab2e39e11a6493412'762 let security = if op.needs_user() {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step763 json!([{ "token": scope }])
Webhooks: every event, to your own addresses, signed and retried764 } else {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step765 json!([{ "token": scope }, {}])
Webhooks: every event, to your own addresses, signed and retried766 };
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step767 let (tool, action) = crate::tools::TOOLS
768 .iter()
769 .find_map(|tool| {
770 tool.actions
771 .iter()
772 .find(|action| action.op == op)
773 .map(|action| (tool.name, action.name))
774 })
775 .unwrap_or_default();
API and MCP server in Rust; a public index at the API root776 let mut described = json!({
Webhooks: every event, to your own addresses, signed and retried777 "operationId": id,
API and MCP server in Rust; a public index at the API root778 "tags": [tag(op)],
Merge branch 'worktree-agent-ab2e39e11a6493412'779 "summary": summary(route, &id),
API and MCP server in Rust; a public index at the API root780 "description": op.description(),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step781 "x-operation": op.name(),
782 "x-mcp-tool": tool,
783 "x-mcp-action": action,
784 "x-scope": scope.first().copied(),
Merge branch 'worktree-agent-ab2e39e11a6493412'785 "security": security,
API and MCP server in Rust; a public index at the API root786 "parameters": parameters,
Merge branch 'worktree-agent-ab2e39e11a6493412'787 "responses": responses,
API and MCP server in Rust; a public index at the API root788 });
789 if !body.is_null() {
790 described["requestBody"] = body;
791 }
792 described
793}
794
795/// Entries for device sign-in, which is not an operation.
796fn onboarding() -> Map<String, Value> {
797 let paths = json!({
Agents as a team: lifecycle, merge queue, billing and a new shell798 "/device/code": {
API and MCP server in Rust; a public index at the API root799 "post": {
800 "operationId": "device_code",
801 "tags": ["Accounts"],
802 "summary": "Start signing in",
Agents as a team: lifecycle, merge queue, billing and a new shell803 "description": "Begins a device sign-in. Show the person `verification_uri_complete` and have them open it in a browser, where they sign in or register and approve the code. Then poll `/device/token`.",
API and MCP server in Rust; a public index at the API root804 "security": [],
805 "requestBody": {
806 "content": { "application/json": { "schema": {
807 "type": "object",
808 "properties": {
809 "client_name": {
810 "type": "string",
811 "description": "What is asking, shown to the person approving. For example, Claude Code.",
812 },
813 },
814 } } },
815 },
816 "responses": { "200": {
817 "description": "The codes for this sign-in.",
818 "content": { "application/json": { "schema": {
819 "type": "object",
820 "properties": {
Agents as a team: lifecycle, merge queue, billing and a new shell821 "device_code": { "type": "string", "description": "Secret. Send it to /device/token." },
API and MCP server in Rust; a public index at the API root822 "user_code": { "type": "string", "description": "Shown to the person, like WDJB-MJHT." },
823 "verification_uri": { "type": "string" },
824 "verification_uri_complete": {
825 "type": "string",
826 "description": "The link to give the person; it carries the code.",
827 },
828 "expires_in": { "type": "integer", "description": "Seconds until the codes expire." },
829 "interval": { "type": "integer", "description": "Seconds to wait between polls." },
830 },
831 } } },
832 } },
833 },
834 },
Agents as a team: lifecycle, merge queue, billing and a new shell835 "/device/token": {
API and MCP server in Rust; a public index at the API root836 "post": {
837 "operationId": "device_token",
838 "tags": ["Accounts"],
839 "summary": "Finish signing in",
840 "description": "Asks whether the person has approved. Poll no faster than the interval. The token is returned once.",
841 "security": [],
842 "requestBody": {
843 "required": true,
844 "content": { "application/json": { "schema": {
845 "type": "object",
846 "required": ["device_code"],
847 "properties": { "device_code": { "type": "string" } },
848 } } },
849 },
850 "responses": { "200": {
851 "description": "The state of the sign-in.",
852 "content": { "application/json": { "schema": {
853 "type": "object",
854 "required": ["status"],
855 "properties": {
856 "status": { "type": "string", "enum": ["pending", "approved", "denied", "expired"] },
857 "token": { "type": "string", "description": "Present when approved." },
858 "username": { "type": "string" },
859 "verified": {
860 "type": "boolean",
861 "description": "Whether the account's email is confirmed.",
862 },
863 },
864 } } },
865 } },
866 },
867 },
868 });
869 match paths {
870 Value::Object(paths) => paths,
871 _ => Map::new(),
872 }
873}
874
Merge branch 'worktree-agent-ab2e39e11a6493412'875
876/// Puts each operation's examples, where it has them, into its request
877/// and response. Path and query values go under `x-example-params` and
878/// `x-example-query`, which tools that build a request can use.
879fn attach_examples(paths: &mut Map<String, Value>) {
880 let examples = examples();
881 for methods in paths.values_mut() {
882 let Some(methods) = methods.as_object_mut() else { continue };
883 for operation in methods.values_mut() {
884 let id = operation["operationId"].as_str().unwrap_or_default().to_owned();
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step885 let name = operation["x-operation"].as_str().unwrap_or_default().to_owned();
886 let Some(example) = examples.get(&id).or_else(|| examples.get(&name)) else {
Merge branch 'worktree-agent-ab2e39e11a6493412'887 continue;
888 };
889 if let Some(notes) = example.get("notes").and_then(Value::as_str) {
890 let description = operation["description"].as_str().unwrap_or_default();
891 operation["description"] = json!(format!("{description}\n\n{notes}"));
892 }
893 if let Some(response) = example.get("response") {
894 let content = &mut operation["responses"]["200"]["content"]["application/json"];
895 if content.is_object() {
896 content["example"] = response.clone();
897 }
898 }
899 if let Some(request) = example.get("request") {
900 let content = &mut operation["requestBody"]["content"]["application/json"];
901 if content.is_object() {
902 content["example"] = request.clone();
903 }
904 }
905 for (key, extension) in [("params", "x-example-params"), ("query", "x-example-query")] {
906 if let Some(values) = example.get(key) {
907 operation[extension] = values.clone();
908 }
909 }
910 }
911 }
912}
913
API and MCP server in Rust; a public index at the API root914pub fn document() -> Value {
915 let mut paths = onboarding();
916 for route in ROUTES {
917 let entry = paths
918 .entry(openapi_path(route))
919 .or_insert_with(|| json!({}));
920 entry[route.method.to_lowercase()] = operation(route);
921 }
Merge branch 'worktree-agent-ab2e39e11a6493412'922 attach_examples(&mut paths);
923 let tags: Vec<Value> = SECTIONS
924 .iter()
925 .map(|(name, description, ops)| {
926 json!({
927 "name": name,
928 "description": description,
929 // The section's operations in reading order, by MCP tool name.
930 "x-tools": ops.iter().map(|op| op.name()).collect::<Vec<_>>(),
931 })
932 })
933 .collect();
934 let codes = ["unauthenticated", "payment_required", "forbidden", "not_found", "conflict", "invalid"];
API and MCP server in Rust; a public index at the API root935 json!({
936 "openapi": "3.1.0",
937 "info": {
938 "title": "g1t API",
939 "version": "1",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API940 "description": "The REST API for g1t, a git forge built for agents. The same operations are available to agents as MCP tools at https://mcp.g1t.sh. Every name in a request or response body is `snake_case`; names you chose, such as a workflow's inputs or a secret's name, are returned as you wrote them.",
API and MCP server in Rust; a public index at the API root941 "license": { "name": "MIT", "identifier": "MIT" },
942 },
943 "servers": [{ "url": "https://api.g1t.sh" }],
944 "security": [{ "token": [] }, {}],
Merge branch 'worktree-agent-ab2e39e11a6493412'945 "tags": tags,
API and MCP server in Rust; a public index at the API root946 "paths": paths,
947 "components": {
948 "securitySchemes": {
949 "token": {
950 "type": "http",
951 "scheme": "bearer",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step952 "description": "An access token, `g1t_…`. Public data needs none. Each operation names the scope a token needs for it; see https://docs.g1t.sh/guides/authentication/#scopes.",
API and MCP server in Rust; a public index at the API root953 },
954 },
955 "schemas": {
956 "Error": {
957 "type": "object",
958 "required": ["error"],
959 "properties": {
960 "error": {
961 "type": "object",
962 "required": ["code", "message"],
963 "properties": {
Merge branch 'worktree-agent-ab2e39e11a6493412'964 "code": { "type": "string", "enum": codes },
API and MCP server in Rust; a public index at the API root965 "message": { "type": "string" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step966 "needed_scope": {
967 "type": "string",
968 "description": "On a 403 for an access token without the scope the call needs: that scope, such as `issues:write`.",
969 },
API and MCP server in Rust; a public index at the API root970 },
971 },
972 },
973 },
974 },
975 },
976 })
977}
978
979#[cfg(test)]
980mod tests {
981 use super::*;
982
983 #[test]
984 fn every_route_is_documented_once() {
985 let document = document();
986 let mut ids = Vec::new();
987 for (_, methods) in document["paths"].as_object().unwrap() {
988 for (_, operation) in methods.as_object().unwrap() {
989 ids.push(operation["operationId"].as_str().unwrap().to_owned());
990 }
991 }
992 for op in Op::ALL {
993 assert_eq!(
994 ids.iter().filter(|id| *id == op.name()).count(),
995 1,
996 "{}",
997 op.name()
998 );
999 }
Webhooks: every event, to your own addresses, signed and retried1000 let mut unique = ids.clone();
1001 unique.sort();
1002 unique.dedup();
1003 assert_eq!(unique.len(), ids.len(), "operation ids repeat");
API and MCP server in Rust; a public index at the API root1004 }
1005
1006 #[test]
1007 fn path_and_query_inputs_are_not_repeated_in_the_body() {
1008 let document = document();
Agents as a team: lifecycle, merge queue, billing and a new shell1009 let merge = &document["paths"]["/repos/{owner}/{name}/pulls/{number}/merge"]["post"];
API and MCP server in Rust; a public index at the API root1010 let body = &merge["requestBody"]["content"]["application/json"]["schema"]["properties"];
1011 assert!(body.get("keep_issue_open").is_some());
1012 assert!(body.get("repo").is_none() && body.get("number").is_none());
Agents as a team: lifecycle, merge queue, billing and a new shell1013 let list = &document["paths"]["/repos"]["get"];
API and MCP server in Rust; a public index at the API root1014 assert_eq!(list["parameters"][0]["name"], "q");
1015 assert!(list.get("requestBody").is_none());
1016 }
1017
1018 #[test]
Merge branch 'worktree-agent-ab2e39e11a6493412'1019 fn every_operation_is_in_one_section() {
1020 for op in Op::ALL {
1021 let sections = SECTIONS
1022 .iter()
1023 .filter(|(_, _, ops)| ops.contains(&op))
1024 .count();
1025 assert_eq!(sections, 1, "{}", op.name());
1026 }
1027 }
1028
1029 #[test]
API and MCP server in Rust; a public index at the API root1030 fn titles_read_as_sentences() {
Merge branch 'worktree-agent-ab2e39e11a6493412'1031 assert_eq!(title(Op::CreateIssue), "Create an issue");
API and MCP server in Rust; a public index at the API root1032 assert_eq!(title(Op::Whoami), "Get the current user");
1033 }
Merge branch 'worktree-agent-ab2e39e11a6493412'1034
1035 #[test]
1036 fn every_operation_has_an_example_response() {
1037 let examples = examples();
1038 assert!(!examples.is_empty(), "reference.json does not parse");
1039 let document = document();
1040 let mut known = Vec::new();
1041 for (path, methods) in document["paths"].as_object().unwrap() {
1042 for (method, operation) in methods.as_object().unwrap() {
1043 known.push(operation["operationId"].as_str().unwrap().to_owned());
1044 let example = &operation["responses"]["200"]["content"]["application/json"]["example"];
1045 assert!(!example.is_null(), "{method} {path} has no example response");
1046 }
1047 }
1048 for id in examples.keys() {
1049 assert!(known.contains(id), "reference.json names {id}, which is not an operation");
1050 }
1051 }
1052
1053 #[test]
1054 fn example_requests_send_only_what_the_body_takes() {
1055 let document = document();
1056 for (path, methods) in document["paths"].as_object().unwrap() {
1057 for (method, operation) in methods.as_object().unwrap() {
1058 let content = &operation["requestBody"]["content"]["application/json"];
1059 let Some(example) = content["example"].as_object() else { continue };
1060 let properties = &content["schema"]["properties"];
1061 for key in example.keys() {
1062 assert!(!properties[key].is_null(), "{method} {path}: {key} is not in the body");
1063 }
1064 }
1065 }
1066 }
1067
1068 /// The docs site's copy of the document. Run with `G1T_WRITE_OPENAPI=1`
1069 /// to rewrite it after changing an operation.
1070 #[test]
1071 fn the_docs_copy_is_current() {
1072 let path = concat!(env!("CARGO_MANIFEST_DIR"), "/../docs/src/data/openapi.json");
1073 let current = serde_json::to_string_pretty(&document()).unwrap() + "\n";
1074 if std::env::var_os("G1T_WRITE_OPENAPI").is_some() {
1075 std::fs::write(path, &current).unwrap();
1076 return;
1077 }
1078 let copy = std::fs::read_to_string(path).unwrap_or_default().replace("\r\n", "\n");
1079 assert!(
1080 copy == current,
1081 "apps/docs/src/data/openapi.json is out of date: run G1T_WRITE_OPENAPI=1 cargo test -p g1t-api openapi"
1082 );
1083 }
API reference: no example reads as a real secret1084
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API1085 /// The reference shows responses as they are sent: `snake_case`.
1086 #[test]
1087 fn example_responses_are_snake_case() {
1088 let document = document();
1089 for (path, methods) in document["paths"].as_object().unwrap() {
1090 for (method, operation) in methods.as_object().unwrap() {
1091 let example = &operation["responses"]["200"]["content"]["application/json"]["example"];
1092 let leaked = g1t_kit::wire::camel_case_keys(example);
1093 assert!(leaked.is_empty(), "{method} {path} shows {leaked:?}");
1094 }
1095 }
1096 }
1097
API reference: no example reads as a real secret1098 /// Examples never hold anything that reads as a real credential, which
1099 /// secret scanners rightly flag in a public repository: they end in `…`
1100 /// after the prefix, as `whsec_…` and `g1t_…` do.
1101 #[test]
1102 fn examples_hold_no_real_looking_secrets() {
Fast pages, required checks on the branch, self-hosted runners, honest incidents1103 let prefixes = ["whsec_", "g1t_", "g1tr_", "g1trt_", "sk_live_", "sk_test_", "ghp_", "github_pat_", "xoxb-", "AKIA"];
API reference: no example reads as a real secret1104 for (line, text) in REFERENCE.lines().enumerate() {
1105 for prefix in prefixes {
1106 let mut rest = text;
1107 while let Some(at) = rest.find(prefix) {
1108 let after = &rest[at + prefix.len()..];
1109 let run = after.chars().take_while(|c| c.is_ascii_alphanumeric()).count();
1110 assert!(
1111 run < 12,
1112 "reference.json line {}: `{prefix}` followed by {run} characters reads as a real secret; write `{prefix}…`",
1113 line + 1
1114 );
1115 rest = after;
1116 }
1117 }
1118 }
1119 }
API and MCP server in Rust; a public index at the API root1120}

This file's history is long; its oldest lines are credited to the oldest commit read.